Tenant isolation
Every runtime starts from tenant config, allowed origins, tenant-specific branding, and scoped credentials.
Trust
Clara is designed around tenant boundaries, domain verification, API keys, config-driven runtime behavior, and operational visibility.
Every runtime starts from tenant config, allowed origins, tenant-specific branding, and scoped credentials.
Setup Console controls domains, user access, API keys, install snippets, and verification state.
Tenant Console organizes conversations, activity, knowledge, and health into operations-ready surfaces.
When providers are unavailable, Clara presents customer-friendly states instead of exposing raw infrastructure errors.
Security model
Clara treats tenant identity, workflow permissions, connector access, and operational evidence as runtime boundaries rather than optional prompt instructions.
Runtime configuration, knowledge, credentials, connector bindings, and customer operations are resolved for the authenticated tenant. Request bodies cannot override that tenant identity, and the platform does not fall back to a shared demo provider when an exact binding is missing.
Only enabled, connector-backed workflows can mutate external systems. Workflow tools define the permitted operation, and replay-safe operation identities protect retries from duplicating side effects.
Clara uses stable failure and handoff directives when workflow preparation or selection cannot complete. Knowledge failures do not become invented answers, telemetry failures do not break the customer response, and raw infrastructure errors are not exposed to customers.
Correlation identifiers span channels, runtime tools, connectors, and tenant systems. Searchable timelines record outcomes and stable error codes while sensitive values must be redacted before logs or evidence are stored.
Can Clara resolve our payment failures without exposing private data?
Can Clara guide users through appointment or subscription changes?
Can Clara understand which page and workflow the customer is on?
Can our team control domains, snippets, knowledge, and tenant settings?
Can we test real demos instead of watching a canned video?